8.1 Centralized vs Decentralized, Flat vs Traditional, In-Person vs Remote

Key Takeaways

  • CIA Part 2 A5f is an engagement-risk skill: convert centralized vs decentralized, flat vs traditional, and in-person vs remote work into effects on control ownership, SOD, monitoring, local override, and evidence — not into org-chart trivia
  • Centralizing AP into shared services lowers plant-level payment-release risk in the ERP but concentrates hub override and can hide remaining plant risk in receiving, goods receipts, and standing data that still sit locally
  • Decentralized small sites often cannot segregate initiate, approve, record, and reconcile even when the corporate policy looks complete; you have multiple populations, not one
  • Flat structures create incompatible duties and informal approvals; traditional hierarchies create rubber-stamp reviews and filtered reporting — neither label is automatically higher or lower residual risk
  • Remote work is the auditee’s environment (this objective). Remote auditing is the internal audit team’s approach (Chapter 6 / A4). CIA Part 2 itself is Pearson VUE test-center only; OnVUE ended 27 May 2025
Last updated: August 2026

8.1 Centralized vs Decentralized, Flat vs Traditional, In-Person vs Remote

Quick Answer: Structure and work environment change five planning facts: who owns each control, whether segregation of duties (SOD) can actually exist, how monitoring runs, how easy local override is, and what evidence you can collect. CIA Part 2 A5f tests that conversion, not org-chart vocabulary. Keep three ideas apart: the auditee’s remote work model, the internal audit team’s remote auditing approach (Chapter 6), and the CIA exam’s Pearson VUE test-center rule.

When you plan an engagement under the 2025 CIA Part 2 syllabus, official objective A5f asks you to recognize the impact of different organizational structures and environments on the risk assessment, including centralized versus decentralized, flat versus traditional, and in-person versus remote work. That sits inside Section A, Engagement Planning (50% of the exam), as part of the engagement risk assessment. The professional home is Global Internal Audit Standards (GIAS) Domain V, Principle 13, Plan Engagements Effectively, especially Standard 13.2 Engagement Risk Assessment. You are not decorating the planning memo with an org chart. You are deciding where residual risk sits before you freeze objectives, scope, and the work program.

The same accounts-payable narrative can be two different engagements. A manufacturer with a clerk, a controller, and a posting accountant at every plant is not the same population, the same SOD story, or the same evidence plan as a manufacturer that posts every invoice in a headquarters shared-services hub. If you copy last year’s procedures onto this year’s design, you will sample the wrong place and miss the override that the new design actually allows.

Why structure is a risk driver, not background color

A control that looks complete on a policy PDF can still leave high residual risk if the design of the organization makes the control unworkable. Four people cannot implement initiate / approve / record / reconcile. A founder who sits in every decision will override whatever matrix you print. A fully remote payroll team will not give you observational evidence of live check distribution no matter how many hours you budget to “watch the process.”

Part 2 planners use structure to answer five questions on this activity, this period:

  1. Control ownership — Who is actually accountable for the control, and do they also perform incompatible duties?
  2. Segregation of duties — Can the design support split custody, authorization, recording, and reconciliation — in the system and in real life?
  3. Monitoring — Who reviews exceptions, how fast do they see them, and can the reviewer also process the exception?
  4. Local override — Who can step off the standard path (plant general manager, hub super-user, team lead on chat) without a durable record?
  5. Evidence collection — Will you get one ERP extract and a hub walk-through, or eight plant binders, shared drives, and screen-shares?

Write those five into the engagement risk assessment. Labeling the company “decentralized” and stopping there is not A5f. The exam wants the implication.

Centralized versus decentralized

Centralized designs pull decision rights, standing data, and often transaction processing toward headquarters or a shared-services center. Decentralized designs push those rights to plants, regions, countries, or product lines.

DimensionCentralized / shared servicesDecentralized / local plants
Control ownershipFew named owners; policies and system roles are meant to be uniformOwnership fragments by site; local managers quietly rewrite the process
SODEasier to design in a large team and one ERP role matrixSmall sites combine initiate, approve, and post because there is nobody else
MonitoringOne dashboard, one exception queue, one sample frameQuality tracks the local manager; headquarters may see only summary totals
Local overrideLower on the local payment path if the hub reviews exceptions; concentrated in hub super-usersHigh: plant controller or general manager can pressure the clerk off-policy in the room
EvidenceStandard extracts, one process-owner interview, one hub walk-throughMultiple locations, local folders, shadow spreadsheets, travel or per-site remote access

Centralization is not a free risk reduction. It concentrates risk. A shared-services AP team that processes every plant can process a fictitious vendor for every plant. One access-admin mistake grants incompatible roles enterprise-wide. Your assessment should ask whether hub-level override and concentration risk replaced the plant-level override you just removed.

Decentralization is not automatically chaos. Corporate rails — a single ERP, a locked vendor master, system-enforced dual approval — can bind local behavior. Your job is to test whether those rails actually prevent the local workaround, not to assume they do because a slide says “one process.”

Scenario: local plant AP versus centralized shared services

A manufacturer runs eight plants. The exam loves to swap these two designs in a stem. Work them once so you can recognize either one in 72 seconds.

Design A — local AP. Each plant receives invoices. A plant controller approves them. A plant accountant posts to a local company code. Vendor-master changes happen at the plant. Month-end is a PDF package emailed to headquarters.

Engagement implications: duplicate and fictitious local vendors, and “pay it anyway” overrides from the plant general manager, are core residual risks. SOD at a 15-person plant is often a slogan. Evidence is scattered — shared drives, email approvals, binders. You have eight populations, not one. A walk-through at headquarters will not show how Plant 6 pays freight brokers. Budget multi-site procedures or a risk-based site sample. Do not treat the headquarters policy as operating effectiveness at the dock.

Design B — centralized shared services. Invoices are captured to a hub. Three-way match runs in the ERP. Vendor master is a headquarters-only role. Plants can request a payment; they cannot release it.

Engagement implications: ownership is clearer. SOD can be designed and tested in the role matrix. Monitoring is a hub exception report. Local payment override is harder in the system — but the plant can still create the loss upstream by receiving goods that were never ordered, inflating goods-receipt quantities, or calling a hub processor off-channel. Evidence concentrates: one extract, one hub walk-through, plus tests of plant-originated receiving and purchasing data that the hub trusts. If you stop at the hub and call plants out of scope, you audited the posting factory and missed the fraud factory.

Recent centralization is itself a risk. Dual processes, leftover plant user IDs, and “temporary” local exceptions usually outlast the go-live announcement. Ask what still happens outside the hub during the first two close cycles, and who can still post locally “just in case.”

Flat versus traditional hierarchies

Traditional (hierarchical) structures stack layers: operator → supervisor → manager → director → vice president. Flat structures collapse layers so a small leadership group sits next to the work.

DimensionTraditional hierarchyFlat structure
Control ownershipNamed by title and layer; the RACI looks complete on paperThe same person owns several steps; titles lag the real job
SODReview layers exist; the typical failure is rubber-stamp reviewMissing layers: the doer is also the “reviewer”
MonitoringCascading reports; news is delayed and filtered on the way upFast and informal; weak proof of what anyone actually saw
OverrideMiddle managers override downward; senior override may be invisible on the floorFounder or executive override is in the room; “just do it” is the working rule
EvidenceTickets, stamps, layered sign-offs — volume of paper is not quality of reviewChat threads, hallway decisions, shared inboxes; you reconstruct who decided

Exam trap: flat is not always higher risk, and traditional is not always lower. A seven-layer bank in which every layer initials without reading still has high residual risk. Diffusion of responsibility (“I thought the next layer caught it”) is a traditional-structure failure mode. A flat software team with two-person maker-checker on production deploys and immutable logs can have lower change-management residual risk than a hierarchical plant that files corrective-action forms nobody reads.

Planning translation: map actual decision rights, not the pretty chart. Who can commit spend, who can change standing data, who can suppress an exception? In a traditional org, test whether reviews are substantive — evidence of challenge, not just a stack of initials. In a flat org, test whether informal approvals are reconstructable and whether one person holds an incompatible combination of duties. Shared inboxes, a single “emergency” user ID, and a founder who also administers ERP roles are classic flat-org SOD breaks.

In-person versus remote work — the auditee’s environment

This subsection is about how the activity under review operates, not about how internal audit staffs the job.

In-person work gives you physical observation: who badges in, who sits on the cash drawer, whether blank check stock is locked, whether the receiving dock is empty at lunch. Corridor conversation often reveals the workaround that never made it into the SOP. Collusion is still possible — two people at two desks can still agree to steal — but you can at least see who is present.

Remote and hybrid work move the control surface to identity, devices, VPN, and digital workflow. Physical custody may still exist: inventory in a warehouse, laptops, check stock in a home office. SOD can look perfect as two user IDs and still fail if partners, roommates, or “I’ll text you my code” sharing happens off camera. Monitoring is logs and queues, not a supervisor glancing across the room. Override becomes a channel problem: a manager messages a processor on a personal phone and the processor keys the exception with no ticket. Time-zone spread can mean overnight releases that nobody in headquarters reviews until the loss has already posted.

DimensionIn-person workRemote / hybrid work
Control ownershipTied to desks, shifts, and physical custodyTied to system IDs, VPN roles, and who holds the authenticator
SODVisual two-person presence; collusion is still possibleLogical two-ID presence; credential sharing is the residual risk
MonitoringObservation, cameras where lawful, floor presenceAccess logs, exception queues; “camera on” is not a control by itself
OverrideVerbal pressure on the floor; after-hours office accessAfter-hours VPN, admin tokens at home, unrecorded chat pressure
EvidenceObservation memos, physical counts, photos where allowedLogs, screen-share walk-throughs, ticket history; you may never see the room

If payroll is fully remote, do not write a procedure that depends on watching live check distribution. Rewrite around access provisioning, dual control of the payment file, and whether the same person can change bank details and release the file. If the warehouse is still in-person while finance is remote, your evidence mix should split: observation and counts at the dock; logs and dual-control tests in finance. Hybrid work at the auditee is not the same decision as a hybrid audit approach.

Three ideas the exam will try to blend

Wrong-answer stems often mix these. Keep them in separate boxes.

  1. Remote work — the auditee’s operating model. It changes engagement risk (this objective, A5f): custody, SOD, monitoring, override channels, and what evidence even exists.
  2. Remote auditing — internal audit’s approach to performing the engagement (A4, Chapter 6). Video walk-throughs, not traveling to the plant, and pulling data from off-site are methodology and evidence-reliability choices. They are not the same fact as “the AP clerks work from home.” You can remotely audit an in-person warehouse (poor fit for existence). You can sit on-site to audit a fully remote payroll team (you will still need logs).
  3. CIA exam delivery — Pearson VUE test center only. The IIA discontinued OnVUE online testing on 27 May 2025. You cannot sit Part 2 from your living room. That is candidate logistics, not engagement planning.

A stem about AP moving to work-from-home is about environment and evidence. A stem about the chief audit executive assigning the engagement to be performed entirely off-site is about remote auditing. A stem about where you take CIA Part 2 is about Pearson VUE.

Convert the label into procedures

Do not stop at the adjective. Standard 13.2 is satisfied when the file shows you used structure to change what you will test and how you will evidence it.

  • Ownership: Obtain the org chart and the system-role listing. They will disagree. The disagreement is the finding seed, not a filing problem.
  • SOD: Hunt small sites, shared inboxes, emergency IDs, and plant super-users. In hubs, hunt the few people who can both process transactions and administer access.
  • Monitoring: Who reviews the exception report, how often, and can they also clear the exception? A hub dashboard that nobody opens is not monitoring.
  • Override: Plan procedures for off-system instructions — email, chat, “paid per GM,” after-hours releases, local receiving without a purchase order.
  • Evidence: Match method to design. Hub extract for shared services; multi-site sample for plant AP; logs plus screen-share for remote teams; observation for in-person cash and inventory.

If the structure changed this year, treat the change as its own risk: orphaned access, dual paths, incomplete training, and a month-end that still uses the old local spreadsheet “until the hub catches up.” Chapter 7’s emerging-risk and change material is the companion; this section is the structural why.

The testable rule: name the design, then name the five effects, then change the work program. Fashionable org labels are not a risk assessment.

Loading diagram...
How structure feeds the engagement risk assessment (CIA Part 2 A5f)
Illustrative local-override residual concern by design (planning heuristic, not a published metric)
Test Your Knowledge

A manufacturer moved plant accounts payable into a headquarters shared-services hub last quarter. Plants still perform receiving and can enter goods receipts. Which planning implication is most consistent with CIA Part 2 A5f?

A
B
C
D
Test Your Knowledge

Which statement correctly separates remote work, remote auditing, and CIA exam delivery?

A
B
C
D
Test Your Knowledge

In a flat organization where the founder also approves expenses in a shared inbox, what is the most typical segregation-of-duties implication for the engagement risk assessment?

A
B
C
D